回复:顽固的东东请指点
用费尔木马强力清除助手删除以下文件,勾选“
抑制文件再生”
http://dl.filseclab.com/down/powerrmv.zipC:\DOCUME~1\bobo\LOCALS~1\Temp\~wxp2ins.609.tmp
C:\WINDOWS\system32\drivers\msosmsfpfis64.sys
sreng启动项目,注册表,删除
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FuckJacks.exe]
<IFEO[FuckJacks.exe]><egomoo1.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Logo1_.exe]
<IFEO[Logo1_.exe]><egomoo1.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OSO.exe]
<IFEO[OSO.exe]><egomoo1.exe> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundl132.exe]
<IFEO[rundl132.exe]><egomoo1.exe> [N/A]
sreng-〉启动项目-〉服务-〉驱动程序,删除
[Atixeve2750 / Atixeve2750][Stopped/Manual Start]
<\??\C:\DOCUME~1\bobo\LOCALS~1\Temp\~wxp2ins.609.tmp><N/A>
[msfpfis64 / msfpfis64][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\drivers\msosmsfpfis64.sys><N/A>
AppInit_DLLs正常